Legal

Privacy Policy

What onelinktoken collects, why we collect it, how long we keep it, and who processes it on our behalf.

Effective date: [Effective date] · Version: draft

Draft for legal review — not legal advice

This document is a working draft prepared for review by qualified counsel. It is not legal advice and is not yet the operative privacy notice for onelinktoken. Every bracketed value — for example [Legal entity name] or [Retention period] — must be completed, and the document reviewed in full, before publication.

1. Who we are

onelinktoken is a one-time token and magic-link service operated by [Legal entity name] (“we”, “us”), registered at [Registered address]. This policy covers the onelinktoken website at onelinktoken.com, the onelinktoken REST API, and the onelinktoken MCP server.

For most of what we handle, we act as a processor on behalf of the customer whose account issued the token. That customer decides which end-user data is sent to us. For our own account, billing, and support records we act as a controller. Where a data processing agreement is in place, that agreement governs.

2. Data we collect

Category What it includes Source
Account data Account and tenant identifiers, sign-in identity, plan, API key metadata. You / your IdP
Token records Token type, target address supplied by you, expiry, max uses, status, redirect URL, and a SHA-256 hash of the token value. Your API / MCP calls
Audit events Create, redeem, and revoke events with timestamp, IP address, user agent, and acting identity. Automatic
Operational logs Request metadata, rate-limit counters, and error traces used to run and secure the service. Automatic
Billing data Plan, subscription state, and invoice records. Card details are handled by our payment processor and never reach our servers. You / Stripe

We never store raw token values

A magic link, OTP, or bearer token is returned to the caller once, at creation. What we persist is a SHA-256 hash of the value, used to validate a later redemption. We cannot reconstruct or re-issue the original token, and neither we nor an attacker with database access can read it out of storage.

We do not sell personal data, we do not run advertising trackers on this site, and we do not use customer token data to train machine-learning models.

3. Why we process it

4. Retention

Retention periods below are placeholders pending review and must be confirmed against the product's actual database and log configuration before this page is published.

5. Subprocessors

We use the third parties below to run the service. Any entry marked [Subprocessor] is a placeholder that must be replaced with the confirmed vendor, purpose, and processing location before publication.

Subprocessor Purpose Data reached
Stripe Payment processing and subscription billing Billing contact, payment details (held by Stripe, not by us)
Resend Transactional email delivery for magic links and OTPs Recipient email address, message content
Keycloak (auth.pnebula.com) Identity provider for account sign-in and SSO Sign-in identity, session metadata
[Subprocessor] Cloud hosting and managed database [Confirm before publishing]
[Subprocessor] Monitoring, logging, and error tracking [Confirm before publishing]

Where personal data moves between jurisdictions, transfers rely on [Transfer mechanism]. Primary processing region: [Processing region].

6. Your rights

Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent where processing relies on consent. You can also complain to your local supervisory authority.

If the data was sent to us by a customer using onelinktoken to authenticate you, that customer is the controller — we will forward your request to them and support them in answering it. We aim to respond to rights requests within [Statutory response window].

7. Security

Controls in place today include hash-only token storage, single-use tokens by default, short configurable expiry, hot revocation, per-tenant and per-IP rate limits, encryption in transit, and an append-only audit trail of every create, redeem, and revoke.

Compliance posture — design intent, pending review

onelinktoken is designed against the control expectations of SOC 2, HIPAA, and GDPR. This document makes no assertion that any audit has been completed, that any certification has been issued, or that a Business Associate Agreement is available on any given plan. If you need current attestation status, an executed DPA, or a BAA, ask us and we will tell you exactly where things stand. [Marked for review: confirm attestation status and align with site-wide marketing claims.]

No system is perfectly secure. If you believe you have found a vulnerability, please use the reporting route on our support page rather than a public channel.

8. Cookies and site analytics

This marketing site does not set advertising cookies. Any cookie used by the dashboard is strictly necessary for sign-in and session management. Current analytics configuration: [Analytics tooling — confirm or state "none"].

9. Children

onelinktoken is a developer tool sold to businesses. It is not directed at children, and we do not knowingly collect data from children under [Minimum age].

10. Changes to this policy

We will post any change on this page and update the effective date. For material changes affecting existing customers we will give notice at least [Notice period] in advance by email or in the dashboard.

11. Contact

Privacy questions, rights requests, and DPA requests:

  • Privacy contact: [DPO / privacy contact email]
  • Postal: [Registered address]
  • Entity: [Legal entity name]

For anything that is not a privacy matter, see Support.